CVE Vulnerabilities

CVE-2017-16875

Published: Nov 17, 2017 | Modified: Sep 02, 2021
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
LOW

An issue was discovered in Teluu pjproject (pjlib and pjlib-util) in PJSIP before 2.7.1. The ioqueue component may issue a double key unregistration after an attacker initiates a socket connection with specific settings and sequences. Such double key unregistration will trigger an integer overflow, which may cause ioqueue backends to reject future key registrations.

Affected Software

Name Vendor Start Version End Version
Pjsip Teluu * 2.7.1 (excluding)
Pjproject Ubuntu artful *
Pjproject Ubuntu esm-apps/xenial *
Pjproject Ubuntu trusty *
Pjproject Ubuntu upstream *
Pjproject Ubuntu xenial *
Pjproject Ubuntu zesty *

References